Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8811Nuclei 4349Metasploit 3488✓ solo verificadosrecientespopularesriesgo
22.657 exploits
Referência
CVE-2026-7694
Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7689
Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification
33RIESGO
abrir ↗Referência
CVE-2026-7687
langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
33RIESGO
abrir ↗Referência
CVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir ↗Referência
CVE-2016-7287
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c
35RIESGO
abrir ↗Referência
CVE-2014-4113
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Referência
CVE-2026-9386
Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-9385
Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-9376
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-9372
ItzCrazyKns Vane Model Provider API route.ts server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-9370
ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
33RIESGO
abrir ↗Referência
CVE-2026-10871
Shibby Tomato Web UI rc start_6rd_tunnel os command injection
41RIESGO
abrir ↗Referência
CVE-2026-50266
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
28RIESGO
abrir ↗Referência
CVE-2019-25745
WordPress Plugin Google Review Slider 6.1 SQL Injection via tid
41RIESGO
abrir ↗Referência
CVE-2020-37244
WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx
41RIESGO
abrir ↗Referência
CVE-2020-37243
WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS
41RIESGO
abrir ↗Referência
CVE-2026-10809
itsourcecode Fees Management System manage_user.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7678
YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7443
BurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection
33RIESGO
abrir ↗Referência
CVE-2012-1465
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.